Vulnerabilities in Apache Software Foundation

2,378 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-36364—Apache Calcite Avatica JDBC driver `httpclient_impl` connection property can be used as an RCE vectorEPSS 3.2%CVE-2017-17836—In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases usedEPSS 3.2%CVE-2017-15699—A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vulnerability, a remoteEPSS 3.2%CVE-2018-1310—Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActEPSS 3.2%CVE-2020-17528—Apache NuttX (incubating) Out of Bound Write from invalid TCP Urgent lengthEPSS 3.2%CVE-2024-38477HIGHApache HTTP Server: Crash resulting in Denial of Service in mod_proxy via a malicious requestEPSS 3.2%CVE-2024-23946MEDIUMApache OFBiz: Path traversal or file inclusionEPSS 3.1%CVE-2012-3353—The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files iEPSS 3.1%CVE-2018-1316—The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name was allowing directoEPSS 3.1%CVE-2024-52577CRITICALApache Ignite: Possible RCE when deserializing incoming messages by the server nodeEPSS 3.1%CVE-2024-56512LOWApache NiFi: Missing Complete Authorization for Parameter and Service ReferencesEPSS 3.1%CVE-2017-3157—By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a fEPSS 3.1%CVE-2018-8023—Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions EPSS 3.1%CVE-2021-31812—A carefully crafted PDF file can trigger an infinite loop while loading the fileEPSS 3.1%CVE-2021-41561—Apache Parquet-MR potential DoS in case of malicious Parquet fileEPSS 3.1%CVE-2021-30129—DoS/OOM leak vulnerability in Apache Mina SSHD ServerEPSS 3.0%CVE-2017-12620—When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only aEPSS 3.0%CVE-2023-50292HIGHApache Solr: Solr Schema Designer blindly "trusts" all configsets, possibly leading to RCE by unauthenticated usersEPSS 3.0%CVE-2023-45802—Apache HTTP Server: HTTP/2 stream memory not reclaimed right away on RSTEPSS 3.0%CVE-2014-0043—In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of partiEPSS 3.0%